Are there any security risks with allowing internet traffic to be forwarded inside your local network? (genuinely curious my networking knowledge is a bit lacking)
Any normal attacks that could be executed against a server on the internet could now be executed against your local server.
Which means, if your local/dev API endpoints have vulnerabilities, you will be exposed.
To help protect against attacks, you will want to block all 3rd party requests.
A possible solution would be to use HTTP basic auth (assuming tunnelto passes along the basic auth headers).
Ex. https://user:pass@t1.tunnelto.dev/api/hello
Then on your local/dev server, check user & pass.